Re: [v6ops] new draft: draft-taylor-v6ops-fragdrop

Fernando Gont <fgont@si6networks.com> Tue, 23 October 2012 08:51 UTC

Return-Path: <fgont@si6networks.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C8DD321F868B for <v6ops@ietfa.amsl.com>; Tue, 23 Oct 2012 01:51:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.473
X-Spam-Level:
X-Spam-Status: No, score=-2.473 tagged_above=-999 required=5 tests=[AWL=0.126, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id k9B3ZdNQgFzg for <v6ops@ietfa.amsl.com>; Tue, 23 Oct 2012 01:51:48 -0700 (PDT)
Received: from web01.jbserver.net (web01.jbserver.net [IPv6:2a00:d10:2000:e::3]) by ietfa.amsl.com (Postfix) with ESMTP id 4965021F8654 for <v6ops@ietf.org>; Tue, 23 Oct 2012 01:51:47 -0700 (PDT)
Received: from [186.134.9.99] (helo=[192.168.123.120]) by web01.jbserver.net with esmtpsa (TLSv1:CAMELLIA256-SHA:256) (Exim 4.76) (envelope-from <fgont@si6networks.com>) id 1TQaD5-0008JW-S5; Tue, 23 Oct 2012 10:51:40 +0200
Message-ID: <50865A96.1080602@si6networks.com>
Date: Tue, 23 Oct 2012 05:51:34 -0300
From: Fernando Gont <fgont@si6networks.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:16.0) Gecko/20121011 Thunderbird/16.0.1
MIME-Version: 1.0
To: Mark Andrews <marka@isc.org>
References: <201210161245.q9GCj0i26478@ftpeng-update.cisco.com> <E1829B60731D1740BB7A0626B4FAF0A65E0DEDF3A2@XCH-NW-01V.nw.nos.boeing.com> <507DA6A3.20807@inex.ie> <E1829B60731D1740BB7A0626B4FAF0A65E0DEDF3C3@XCH-NW-01V.nw.nos.boeing.com> <507DAB13.2010704@inex.ie> <E1829B60731D1740BB7A0626B4FAF0A65E0DEDF3CE@XCH-NW-01V.nw.nos.boeing.com> <507DDF8A.9010607@inex.ie> <E1829B60731D1740BB7A0626B4FAF0A65E0DEDF5AB@XCH-NW-01V.nw.nos.boeing.com> <BB219517-B488-4777-AE9C-35C57BE91263@kumari.net> <Pine.LNX.4.64.1210171337470.7337@shell4.bayarea.net> <AC530E99-4054-4B0A-9B5C-30F9EF4A530C@kumari.net> <20121018223121.28B2C2A0041D@drugs.dv.isc.org>
In-Reply-To: <20121018223121.28B2C2A0041D@drugs.dv.isc.org>
X-Enigmail-Version: 1.4.5
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Cc: V6 Ops <v6ops@ietf.org>
Subject: Re: [v6ops] new draft: draft-taylor-v6ops-fragdrop
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 Oct 2012 08:51:50 -0000

On 10/18/2012 07:31 PM, Mark Andrews wrote:
>> Yes, and part of the reason that packets are not reaching the core infrastr=
>> ucture at line rate is because operators have the ability to examine traffi=
>> c destined for the core infrastructure and filter / rate-limit it to someth=
>> ing reasonable. I may want to allow e.g traceroute to "core" stuff and toss=
>>  that in one rate-limit bucket, but never allow SSH towards my core.  If I =
>> have fragments I have no way of knowing what they are supposed to be part o=
>> f, and so, er=85 =
> 
> So you want allow fragmented ICMP directed at core routers through and are worried
> that some non initial TCP fragments might make it through.  As far as I can tell
> letting through non initial TCP fragments doesn't increase your risk or attack
> surface at all.

If the end-system does not implement RFC5722, then allowng non-initial
fragments might still mean you're not filtering what you expected to be
filtering.

FWIW, we seem to be converging towards RFC5722, but that doesn't mean
everyone is there (e.g., see:
<http://blog.si6networks.com/2012/02/ipv6-nids-evasion-and-improvements-in.html>).

Cheers,
-- 
Fernando Gont
SI6 Networks
e-mail: fgont@si6networks.com
PGP Fingerprint: 6666 31C6 D484 63B2 8FB1 E3C4 AE25 0D55 1D4E 7492